Managing CM Connections using GUI
This section explains the steps to configure the CM/external CM connections using GUI.
Prerequisites
On the client CM.
On the domain of the external CM where you want to create a connection.
After completing the steps, configure the CM connection on the client CM.
Create a CipherTrust (External) Connection
Add a connection to the external CipherTrust Server.
Log on to the CipherTrust Manager.
In the left pane, click Access Management > Connections.
On the Connections screen, under CIPHERTRUST (EXTERNAL) CONNECTIONS, click Add CipherTrust (external) Server.
On the Add CipherTrust (external) Server screen, enter the Name of a CipherTrust (external) Server.
Enter the Node Hostname/IP of a CipherTrust Manager server node (external CM).
Note
If the external CM is configured to use a custom port (that is, other than
443
), then append the custom port to the hostname/IP address. For example, specify<hostname or IP address>:<custom-port>
.To add additional nodes, click Add CM Node.
Add a Certificate. You need to add the root CA of the external CM. The options are:
File Upload: Select and upload the certificate (in PEM format).
Text: Select and paste the certificate content.
Sample Root CA:
Note
To add additional nodes, click Add CM Certificate.
The external CM web server certificate must contain the IP address.
Click Add CipherTrust (external) Server.
The newly created CipherTrust (external) Server is displayed in the list of CipherTrust (external) Servers.
Generate a Connection CSR
Navigate to the CSR Generator page (CA > CSR Generator).
Generate a Connection CSR and download the CSR certificate.
Create a Client Profile
Navigate to the Client Profiles page (Access Management > Client Profiles).
Add a client profile.
Note
- You can create a client profile using the Local CA and External CA.
Generate a Registration Token
Refer to Creating a Registration Token for details.
Note
To generate a registration token, you first need to create a client profile.
Add the Client
Navigate to the Client Hub page (Access Management > Client Hub).
Click Add Client.
Specify a name for the client.
Select the Registration Token that you generated.
Add the connection CSR that you generated above. The options are:
File Upload: Select and upload the certificate (in PEM format).
Text: Select and paste the certificate content.
Add the client.
Save the Client ID and the Client Certificate.
If the external CM is in a clustered environment, the external CM administrator needs to add the client to the Cluster Info Viewers group, so that client CM can read the cluster information.
To add the client to the Cluster Info Viewers group.
On the Client Hub page, click the Name of the client that you created above.
Expand the GROUPS section.
Disable Show '<client name>' groups.
Search for
Cluster Info Viewers
.Click Add.
Configure a CM connection
Select the CipherTrust (external) server you created from the drop-down list.
Under Authentication:
Enter the Client ID (for example,
18455d84-1b39-48d5-ac86-c649f78703a2
) that you saved while adding the client.Add the Client Certificate that you saved while adding the client. The options are:
File Upload: Select and upload the certificate (in PEM format).
Text: Select and paste the certificate content.
Sample Client Certificate:
(Optional) Click Test Credentials to check whether the connection is configured correctly. If the test is successful, the status is
OK
else the status isFail
.Click Next to move to the Add Products screen of the Add Connection wizard.